Malicious PDF — malware analysis report

Static analysis result for SHA-256 f97bbed3492ce796…

MALICIOUS

PDF

79.0 KB Authoring application: Solid Converter PDF
MD5: 69586cb01d8f37e59918b15cdf2b31be SHA-1: a87faf98b1a3d07443ba45a7bab5f39c03f13efa SHA-256: f97bbed3492ce79604bc6a933dfda59dad3cf8c1f88fe1cfbfaf5ab7555381d7
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, forming a link farm. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the heuristic 'PDF_SEO_LINK_FARM' indicate that this document is designed to redirect users to malicious content, likely phishing pages or further malware downloads. The embedded URLs are the primary indicators of this malicious activity.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://merelymelissa.com/uploads/1/3/0/2/130291779/6815764.pdf
    • http://pdxmen.net/uploads/1/3/0/4/130476732/guxexogiz.pdf
    • http://uniquelyyourslandscapes.com/uploads/1/3/0/3/130323599/9858277.pdf
    • http://myessentialguide.com/uploads/1/3/0/7/130776399/4941172.pdf
    • http://1989raiders.com/uploads/1/3/0/7/130739933/falamokogafe.pdf
    • http://michaelmccarthy.net/uploads/1/3/0/7/130776138/lolatolanawo-fepoxaxo.pdf
    • http://onlinewealthtools.net/uploads/1/3/0/7/130739875/482d648bed.pdf
    • http://mineolatrading.com/uploads/1/3/0/5/130543262/8104102.pdf
    • http://levanare.com/uploads/1/3/0/4/130435680/6288846.pdf
    • http://nexuschapel.org/uploads/1/3/0/4/130488839/rezixipe-pipaxodezibifot-kimelojikemefo-xeles.pdf
    • http://adragonflysbnb.ca/uploads/1/3/0/7/130775732/578380.pdf
    • http://townlakebrewing.com/uploads/1/3/0/2/130273616/9a8add9ad27455c.pdf
    • http://spiritofsaron.com/uploads/1/3/0/6/130620840/1395275.pdf
    • http://fanzines.net/uploads/1/3/0/6/130604002/xigiwo.pdf
    • http://catvaloreaza.com/uploads/1/3/0/4/130489377/390202.pdf
    • http://tamilstudies.com/uploads/1/3/0/4/130488513/dff4b8.pdf
    • http://edemtec.com/uploads/1/3/0/6/130604986/594df8ceea.pdf
    • http://puppyparentpro.com/uploads/1/3/0/2/130288402/4923916.pdf
    • http://systecaiml.com/uploads/1/3/0/3/130379078/vaxanu-renasujo-waxapiwobufano.pdf
    • http://stlshrinerslimbreconstruction.com/uploads/1/3/0/7/130776158/tusumipabedalozolow.pdf
    • http://momentumyoutharts.com/uploads/1/3/0/6/130639157/1453164.pdf
    • http://midshiftmedia.com/uploads/1/3/0/4/130478882/aacb5.pdf
    • http://theexplorersguild.club/uploads/1/3/0/6/130621574/aebb3620810a12.pdf
    • http://guiasregionais.com/uploads/1/3/0/7/130738850/1761672.pdf
    • http://pcbaugh.com/uploads/1/3/0/6/130604888/8573c6aca0808.pdf
    • http://united56.pleasingfood.com/uploads/1/3/0/7/130776760/130776760.html#allotropes+of+carbon+notes+pdf
    • http://midshiftmedia.com/uploads/1/3/0/4/130478882/aac

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000017c9.bin
afbb328fd9b6a3d53053a154ff25020b9864e22e3fda38a0d9dbf43587b1b15e
pdf-font-stream PDF embedded font (sfnt) at offset 0x17C9 9620 bytes
font_01_sfnt_off0000e230.bin
5a9695438bb362a8b10d86f415c06da9d71f416851af8c6c9c762304ce3c8158
pdf-font-stream PDF embedded font (sfnt) at offset 0xE230 16088 bytes
font_02_sfnt_off0000f6ed.bin
a13887f4c5a0e0cb777bd4aee259969a21e8d32230372b0752783907e28c8b6e
pdf-font-stream PDF embedded font (sfnt) at offset 0xF6ED 4116 bytes